Malicious PDF — malware analysis report

Static analysis result for SHA-256 baa88e5edc33d653…

MALICIOUS

PDF

23.3 KB Created: 2019-05-02 17:40:04 +01:00 Authoring application: mPDF 5.7
MD5: 94eadf260242edc1118eaf76425171ec SHA-1: 58bc06d2b1b61ffa2ddd5faaf8f36c46b3ada78c SHA-256: baa88e5edc33d6536f1b86c0d04ff5b7475704c7562b7da6721e57b651dc2af3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, as detected by the PDF_SEO_LINK_FARM heuristic. These links point to external PDF documents hosted on a dynamic DNS domain, suggesting a link farm or redirection scheme. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://unieoooq.linkpc.net/64e04e44e24e24e5/O-rabe-do-futuro-2-Uma-juventude-no-Oriente-M-dio-1984-1985-by-Riad-Sattouf.pdf
    • http://unieoooq.linkpc.net/24e64e34e64e04e8/The-Arab-of-the-Future-2-A-Childhood-in-the-Middle-East-1984-1985-A-Graphic-Memoir-by-Riad-Sattouf.pdf
    • http://unieoooq.linkpc.net/34e34e84e44e04e9/The-Arab-of-the-Future-3-A-Childhood-in-the-Middle-East-1985-1987-by-Riad-Sattouf.pdf
    • http://unieoooq.linkpc.net/14e94e24e1/The-Arab-of-the-Future-A-Childhood-in-the-Middle-East-1978-1984-A-Graphic-Memoir-by-Riad-Sattouf.pdf
    • http://unieoooq.linkpc.net/74e54e24e44e14e0/Pascal-Brutal-Coffret-3-volumes-Tome-1-La-nouvelle-virilit-Tome-2-Le-m-le-dominant-Tome-3-Plus-fort-que-les-plus-forts-by-Riad-Sattouf.pdf
    • http://unieoooq.linkpc.net/64e94e54e54e14e7/Oltre-il-New-Age-Il-futuro-della-religione-e-le-religioni-del-futuro-by-Danila-Vista.pdf
    • http://unieoooq.linkpc.net/14e14e34e84e34e54e5/Kandinsky-Album-de-l-exposition-grande-galerie-1er-novembre-1984-28-janvier-1985-by-Wassily-Kandinsky.pdf
    • http://unieoooq.linkpc.net/94e54e14e54e14e8/Escuelas-Del-Futuro-En-Sistemas-Educativos-Del-Futuro-Schools-Of-The-Future-Of-Educational-Systems-Of-The-Future-que-Formacion-Docente-Se-Requiere-What-Teaching-Formation-Do-You-Require-by-In-s-Aguerrondo.pdf
    • http://unieoooq.linkpc.net/54e34e54e34e54e1/Perla-d-Oriente-by-Olivia-Gates.pdf
    • http://unieoooq.linkpc.net/54e94e84e94e84e4/Assassinato-no-Expresso-Oriente-Convencional-by-Agatha-Christie.pdf
    • http://unieoooq.linkpc.net/84e14e04e34e64e5/Al-m-do-Bem-e-do-Mal-ou-Prel-dio-de-uma-filosofia-do-futuro-by-Friedrich-Nietzsche.pdf
    • http://unieoooq.linkpc.net/54e64e84e44e04e6/El-Libro-De-La-Sabiduria-De-Oriente-The-Book-of-the-Oriental-Wisdom-by-Gilbert-Sinou-.pdf
    • http://unieoooq.linkpc.net/64e34e74e24e44e7/Inversiones-La-respuesta-Aprenda-a-administrar-su-dinero-y-a-proteger-su-futuro-financiero-by-Daniel-C-Goldie.pdf
    • http://unieoooq.linkpc.net/94e64e34e54e44e1/Chapas-Sinicas-Macau-E-O-Oriente-Nos-Arquivos-Nacionais-Torre-Do-Tombo-by-Isau-Santos.pdf
    • http://unieoooq.linkpc.net/74e54e24e34e94e4/Always-Me-by-Kelly-Riad.pdf
    • http://unieoooq.linkpc.net/74e14e34e84e24e6/Il-futuro-della-ricchezza---Capitale-intellettuale-e-new-economy-il-focus-dalle-aziende-agli-individui-by-Stan-Davis.pdf
    • http://unieoooq.linkpc.net/74e54e14e94e44e4/Riad-Mimosa-by-James-Orr.pdf
    • http://unieoooq.linkpc.net/24e94e74e24e64e3/Perfect-Imperfection-by-Rasha-Riad.pdf
    • http://unieoooq.linkpc.net/74e54e24e44e14e7/Arab-Response-To-The-Multinationals-by-Riad-A-Ajami.pdf
    • http://unieoooq.linkpc.net/74e54e24e44e24e3/Accounting-Costing-and-Management-by-Riad-Izhar.pdf
    • http://unieoooq.linkpc.net/74e54e24e44e14e0/Pascal-Brutal-Coffret-3-volumes-Tome-1-La-nouvelle-virilit-Tome-2-Le-m-le-dominant-Tome-3-Plus-fort-